Security & Trust
ALLYK Governance
Last updated: August 14, 2026
ALLYK is built for controlled automation: information can be read, reviewed, and turned into a draft before a configured action runs. Security, privacy, and operational controls are part of the product design, but they are not a substitute for a customer's own security program or for independent assurance.
Product Controls
- Authenticated, workspace-scoped access and entitlement checks.
- Human approval and connector-specific policy before governed external actions.
- Archive-first records and operational audit events for sensitive changes.
- Private attachment paths and scoped native-client credentials.
- BYOK secret-redaction boundaries and no-key rules mode.
- Human-reviewed privacy requests, compliance signals, remediation tasks, and evidence records.
Claim Limits
ALLYK is not currently represented as SOC 2 certified, SOC 3 certified, audited, GDPR certified, or CCPA/CPRA certified. A SOC 2 report or public SOC 3 report can only be issued by an independent licensed CPA firm after a defined system is examined. Legal applicability, customer contracts, data-processing agreements, and jurisdiction-specific duties require qualified legal review.
Release Control
Every backend feature domain, browser API route, web workspace, native client, plugin, app page, and first-party Marketplace listing is mapped to a versioned privacy and SOC-readiness register. A release check fails when a new feature surface has no registered data classification, privacy handling, SOC control linkage, customer disclosure, owner, known gap, or release condition. Higher-risk processing, new providers, write connectors, native clients, and research flows require additional human review before activation.
Security Reporting
Do not send passwords, API keys, or exploit details through public forms. Send a minimized report to mail@mayayai.com with enough information to reproduce the issue safely. We will assess the report, contain access where appropriate, preserve evidence, and track remediation through the internal control process.